Re: [w3c/ServiceWorker] should sec-ch-ua headers be visible in FetchEvent.request.headers (#1525)

Is the content of these headers defined anywhere? It isn't clear what they contain.

Is there a security reason to prevent them being visible in the service worker?

I think the `user-agent` header can already be overridden by script, whereas client hints cannot, as they start with `sec-`, although it looks like they may drop that requirement.

Do we know what behaviour _they_ want?

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/ServiceWorker/issues/1525#issuecomment-666440482

Received on Thursday, 30 July 2020 15:12:05 UTC